CVE-2022-37155
HIGH 8.8EPSS 40.0%
RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 39.97% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2022-12-13
- Updated
- 2025-04-22
Proof-of-concept exploits (2)
- Abyss-W4tcher/ab4yss-wr4iteups/blob/ffa980faa9e3598d49d6fb7def4f7a67cfb5f427/SPIP%20-%20P…
- https://spawnzii.github.io/posts/2022/07/how-we-have-pwned-root-me-in-2022/